
Security & GRC Decoded · 2025-09-11 · 54 min
How does a software engineer become a GRC leader? In this episode of Security & GRC Decoded , host Raj Krishnamurthy welcomes Varun Gurnaney , Staff Security Engineer at Apple . Varun shares his journey from writing janky Python scripts for compliance evidence collection to shaping the discipline of GRC engineering at some of the world’s biggest companies. He discusses the cultural and technical gaps between security, engineering, GRC, and audit - and how automation can bridge them. From building one control really well to proving value through audit automation, Varun lays out why the GRC space is hotter than ever. This conversation is a must-listen for anyone navigating compliance at scale. 5 Key Takeaways Compliance ≠ Security : Passing audits is not enough - engineering-driven GRC is the future. Start Small : Automate one control well to prove value before scaling automation. Bridging Teams : Cultural friction between engineering, security, GRC, and audit is real - empathy and communication reduce the pain. Audit Anxiety : Audit automation is about reducing anxiety and toil as much as passing audits.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.